Solved

Reauthenticating an NT 4.0 BDC

Posted on 2002-04-19
6
283 Views
Last Modified: 2013-12-28
Fellow Experts:

I am currently managing a few fairly small military networks.  On one of my networks, I have an NT 4.0 domain set up with one PDC and one BDC.  The domain controllers had some issues and were seperated briefly.  The problem now is that the PDC does not trust the BDC.  Directory replication still occurs from the PDC and one can add / change users, etc on the PDC.  However, it is not possible to add users from the BDC.  It generates the error "There is no user session key for the specified logon session".  Also, errors 3210 and 7023 are present in the event log.  

This problem and resolution is described in Technet Article Q153719 "How to Re-Sync PDC/BDC Trust After Event IDs 3210 and 7023".  Basically, the password-protected channel has been broken and the account associated with the BDC's computer name (BDC$) is lo longer listed with the PDC.  However, the suggested resolution of renaming the computer name (even temporarily) is not feasible as the system is also an Exchange 5.5 server.  

Does anyone have any suggestions regarding how one might readd the computer name to the PDC (possibly a third party tool) so that we will not require a full rebuild of the NT Server and Exchange?  Any ideas would be greatly appreciated.

Sincerely,

Herb
0
Comment
Question by:schreib
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 11

Expert Comment

by:geoffryn
ID: 6960428
Have you tried manually resetting the secure channel?

http://support.microsoft.com/default.aspx?scid=kb;en-us;Q150518 
0
 

Author Comment

by:schreib
ID: 6962609
Geoffry:

Thanks for the feedback.  Actually, both netdom and nltest indicated that the secure channel was still valid.  However, the BDC can still not add users or complete similar tasks and presents the error "There is no user session key for the specified logon session."  Any other ideas would be greatly appreciated.

Herb
0
 
LVL 11

Accepted Solution

by:
geoffryn earned 250 total points
ID: 6962958
Is the time correct on both servers?
0
Don't Cry: How Liquid Web is Ensuring Security

WannaCry is just the start. Read how Liquid Web is protecting itself and its customers against new threats.

 

Author Comment

by:schreib
ID: 6963124
Geoffry:

You are the man!  The clock was off and that was the problem.  Thanks a ton!

Herb
0
 
LVL 11

Expert Comment

by:geoffryn
ID: 6963131
Glad to help.
0
 
LVL 5

Expert Comment

by:mbormann
ID: 9215117
Hey!

I cloned some Windows 2000 machines using Ghost 7.5 Corporate Edition, and when I attempt to join the NT 4 domain I consistently get the above error. I forgot to make sure that the SID was different, I did not use sysprep or Ghostwalker, but afterwards I used the NewSID tool from sysinternals.com. I also deleted machine account in PDC, restarted and recreated. I also tried naming the new computers to a completely new name not present in the Server Manager. BDC is almost always offline and is brought back up every few weeks or so. After spending two days, finally your comment "check teh time" solved m problem.

My time was set to GMT, apparently it doesn't affect machines which have already joined the domain, but affects the new machines joining the domain!

Thanks amigo!
0

Featured Post

Optimize your web performance

What's in the eBook?
- Full list of reasons for poor performance
- Ultimate measures to speed things up
- Primary web monitoring types
- KPIs you should be monitoring in order to increase your ROI

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Windows 10 Creator Update has just been released and I have it working very well on my laptop. Read below for issues, fixes and ideas.
Ever visit a website where you spotted a really cool looking Font, yet couldn't figure out which font family it belonged to, or how to get a copy of it for your own use? This article explains the process of doing exactly that, as well as showing how…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
In this video, viewers are given an introduction to using the Windows 10 Snipping Tool, how to quickly locate it when it's needed and also how make it always available with a single click of a mouse button, by pinning it to the Desktop Task Bar. Int…

627 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question